Fergal McCaffery

dblp:49/3010 · DBLP profile ↗
← Back
98ranked-venue papers
9as first author
11since 2021 · last 2025
0000-0002-0839-8362ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 93 · 9 first-author · 10 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1Computer networks · 1Security and privacy · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Trustworthy Artificial Intelligence in Healthcare: A Proposed Framework
Niamh St John Lynch, Róisín Loughran, Martin McHugh, Fergal McCaffery
EuroSPI (1)4
2025 A Process Assessment Model for AI-Enabled Medical Device Software
Gilbert Regan, Buddhika Jayaneththi, Fergal McCaffery
EuroSPI (1)3
2025 A Review of AI Life Cycle-Related Standards to Address AI-Enabled Medical Device Development
Karla Aniela Cepeda Zapata, Róisín Loughran, Tomás Ward, Fergal McCaffery
EuroSPI (1)4
2024 Towards the Development of a Data Security Risk Management Framework for Medical Device Software AI Models
Buddhika Jayaneththi, Fergal McCaffery, Gilbert Regan
EuroSPI (1)2
2024 Artificial Intelligence-Enabled Medical Device Standards: A Multidisciplinary Literature Review
Niamh St John Lynch, Róisín Loughran, Martin McHugh, Fergal McCaffery
EuroSPI (1)4
2024 An Agile-Based Framework for Addressing Defects in Medical Device Software Development
Misheck Nyirenda, Martin McHugh, Róisín Loughran, Fergal McCaffery
EuroSPI (2)4
2024 An Evaluation of Risk Management Standards and Frameworks for Assuring Data Security of Medical Device Software AI Models
abstract
Data is the backbone of Artificial Intelligence (AI) applications, including Medical Device Software (MDS) AI models which rely on sensitive health data. Assuring security of this sensitive health data is a key requirement for MDS AI models and there should be a structured way to manage the risk caused by data security compromises. Implementing a security risk management standard/framework is an effective way to develop a solid baseline for managing security risks, measuring the effectiveness of security controls and meeting compliance requirements. In this paper, nine risk management standards/frameworks in data/information security, AI, Medical Devices (MDs) and AI-enabled MDs domains are evaluated to identify their gaps and implementation challenges when applying them to assure data security of MDS AI models. The results show that currently there is no specific standard/framework that specifically addresses data security risk management of MDS AI models, and that existing standards/frameworks have several gaps such as complexity of the implementation process; lack of detailed threat and vulnerability catalogues; lack of a proper method for risk calculation/estimation; and lack of risk controls and control implementation details. These gaps necessitate the need for the development of a new data security risk management framework for MDS AI models.
Buddhika Jayaneththi, Fergal McCaffery, Gilbert Regan
ICSOFT2
2024 Preliminary Investigation on Machine Learning and Deep Learning Models for Change of Direction Classification in Running
Pranay Jaiswal, Abhishek Kaushik 0002, Fiona Lawless, Tiago De Melo Malaquias, Fergal McCaffery
IDEAL (1)5
2023 Identifying Agile Practices to Reduce Defects in Medical Device Software Development
Misheck Nyirenda, Róisín Loughran, Martin McHugh, Chris D. Nugent, Fergal McCaffery
EuroSPI (2)5
2022 What Makes Agile Software Development Agile?
abstract
Together with many success stories, promises such as the increase in production speed and the improvement in stakeholders’ collaboration have contributed to making agile a transformation in the software industry in which many companies want to take part. However, driven either by a natural and expected evolution or by contextual factors that challenge the adoption of agile methods as prescribed by their creator(s), software processes in practice mutate into hybrids over time. Are these still agile? In this article, we investigate the question: what makes a software development method agile? We present an empirical study grounded in a large-scale international survey that aims to identify software development methods and practices that improve or tame agility. Based on 556 data points, we analyze the perceived degree of agility in the implementation of standard project disciplines and its relation to used development methods and practices. Our findings suggest that only a small number of participants operate their projects in a purely traditional or agile manner (under 15 percent). That said, most project disciplines and most practices show a clear trend towards increasing degrees of agility. Compared to the methods used to develop software, the selection of practices has a stronger effect on the degree of agility of a given discipline. Finally, there are no methods or practices that explicitly guarantee or prevent agility. We conclude that agility cannot be defined solely at the process level. Additional factors need to be taken into account when trying to implement or improve agility in a software company. Finally, we discuss the field of software process-related research in the light of our findings and present a roadmap for future research.
Marco Kuhrmann, Paolo Tell, Regina Hebig, Jil Klünder, Jürgen Münch, Oliver Linssen, Dietmar Pfahl, Michael Felderer, Christian Prause, Stephen G. MacDonell, Joyce Nakatumba-Nabende, David Raffo, Sarah Beecham, Eray Tüzün, Gustavo López 0001, Nicolás Paez, Diego Fontdevila, Sherlock A. Licorish, Steffen Küpper, Günther Ruhe, Eric Knauss, Özden Özcan Top, Paul M. Clarke, Fergal McCaffery, Marcela Genero, Aurora Vizcaíno, Mario Piattini, Marcos Kalinowski, Tayana Conte, Rafael Prikladnicki, Stephan Krusche, Ahmet Coskunçay, Ezequiel Scott, Fabio Calefato, Svetlana Pimonova, Rolf-Helge Pfeiffer, Ulrik Pagh Schultz Lundquist, Rogardt Heldal, Masud Fazal-Baqaie, Craig Anslow, Maleknaz Nayebi, Kurt Schneider, Stefan Sauer 0001, Dietmar Winkler 0001, Stefan Biffl, M. Cecilia Bastarrica, Ita Richardson
IEEE Trans. Software Eng.24
2021 Expert Review of Taxonomy based Testing: A Testing Framework for Medical Device Software
abstract
This paper details the expert review of a framework developed to implement a novel testing approach called taxonomy-based testing (TBT) for the medical device software domain. This framework proposes three approaches to implement TBT and has been validated by experts from the software testing industry and the medical device software domain. This paper details the results from the expert review. The expert review focused on validating the three approaches to TBT, the benefits of TBT to medical device software development, the accuracy of mappings of testing techniques from ISTQB and ISO/IEC/IEEE 29119-4:2015 to defects from a defect taxonomy, the integration of TBT into the standard test processes, ISTQB and ISO/IEC/IEEE 29119-2:2013 and the structure of the framework. The contribution of this paper is to reveal that (i) the framework is implementable in medical device software organisations that follow the IEC 62304:2006+A1:2015 software development process or that use standard test processes, (ii) using a defect taxonomy could standardise the application of experience-based approaches to software testing and (iii) considering potential defects before writing test cases could identify additional defects for test cases.
Hamsini Ketheswarasarma Rajaram, John Loane, Silvana Togneri MacMahon, Fergal McCaffery
ENASE4
2020 Achieving Data Privacy with a Dependability Mechanism for Cyber Physical Systems
Gilbert Regan, Fergal McCaffery, Pangkaj Chandra Paul, Jan Reich, Ioannis Sorokos, Eric Armengaud, Marc Zeller, Simone Longo
EuroSPI2
2020 A Developer Driven Framework for Security and Privacy in the Internet of Medical Things
Ceara Treacy, John Loane, Fergal McCaffery
EuroSPI3
2020 A Retrospective Study of Taxonomy based Testing using Empirical Data from a Medical Device Software Company
Hamsini Ketheswarasarma Rajaram, John Loane, Silvana Togneri MacMahon, Fergal McCaffery
ICSOFT4
2020 Developer Driven Framework for Security and Privacy in the IoMT
Ceara Treacy, John Loane, Fergal McCaffery
ICSOFT3
2020 Challenges and Working Solutions in Agile Adaptation: Experiences from the Industry
Özden Özcan Top, Onur Demirörs, Fergal McCaffery
IWSM-Mensura3
2020 Development of Health Software using Behaviour Driven Development - BDD
Mohammad Z. Anjum, Silvana Togneri MacMahon, Fergal McCaffery
MODELSWARD3
2020 Improving Multi-domain Stakeholder Communication of Embedded Safety-critical Development using Agile Practices: Expert Review
Surafel Demissie, Frank Keenan, Róisín Loughran, Fergal McCaffery
MODELSWARD4
2020 Quality improvement mechanism for cyber physical systems - An evaluation
abstract
Abstract The future will encompass heavily interconnected, distributed, heterogeneous and intelligent systems which are bound to have a significant economic and social impact. Cyber physical systems (CPS) such as autonomous cars, smart electric grid, implanted medical devices and smart manufacturing are some practical examples of these intelligent systems. However, due to the open and cooperative nature of CPS, assuring their dependability is a challenge. The DEIS project addresses this important and unsolved challenge by developing the concept of a digital dependability identity (DDI). A DDI contains all the information that uniquely describes the dependability characteristics of a CPS or CPS component. DDIs are synthesised at development time and are the basis for the (semi)automated integration of components into systems during development, as well as for the fully automated dynamic integration of systems into systems of systems in the field.
Gilbert Regan, Fergal McCaffery, Pangkaj Chandra Paul, Jan Reich, Eric Armengaud, Cem Kaypmaz, Marc Zeller, Joe Zhensheng Guo, Simone Longo, Eoin O'Carroll, Ioannis Sorokos
J. Softw. Evol. Process.2
2019 Analysis of Attacks and Security Requirements for Wireless Body Area Networks - A Systematic Literature Review
Pangkaj Chandra Paul, John Loane, Gilbert Regan, Fergal McCaffery
EuroSPI4
2019 A Framework for Taxonomy Based Testing Using Classification of Defects in Health Software-SW91
Hamsini Ketheswarasarma Rajaram, John Loane, Silvana Togneri MacMahon, Fergal McCaffery
EuroSPI4
2019 Evaluation of a Dependability Mechanism for Cyber Physical Systems
Gilbert Regan, Fergal McCaffery, Jan Reich, Eric Armengaud, Cem Kaypmaz, Joe Zhensheng Guo, Simone Longo, Eoin O'Carroll
EuroSPI2
2019 Improving Communication in Risk Management of Health Information Technology Systems by means of Medical Text Simplification
abstract
Health Information Technology Systems (HITS) are increasingly used to improve the quality of patient care while reducing costs. These systems have been developed in response to the changing models of care to an ongoing relationship between patient and care team, supported by the use of technology due to the increased instance of chronic disease. However, the use of HITS may increase the risk to patient safety and security. While standards can be used to address and manage these risks, significant communication problems exist between experts working in different departments. These departments operate in silos often leading to communication breakdowns. For example, risk management stakeholders who are not clinicians may struggle to understand, define and manage risks associated with these systems when talking to medical professionals as they do not understand medical terminology or the associated care processes. In order to overcome this communication problem, we propose the use of the “Three Amigos” approach together with the use of the SIMPLE tool that has been developed to assist patients in understanding medical terms. This paper examines how the “Three Amigos” approach and the SIMPLE tool can be used to improve estimation of severity of risk by non-clinical risk management stakeholders and provides a practical example of their use in a ten step risk management process.
Silvana Togneri MacMahon, Marco Alfano, Biagio Lenzitti, Giosuè Lo Bosco, Fergal McCaffery, Davide Taibi 0002, Markus Helfert
ISCC5
2019 Taxonomy-based testing and validation of a new defect classification for health software
abstract
Abstract Defect‐based testing is a powerful tool for finding errors in software. Many software manufacturers avoid this method because it requires a detailed defect taxonomy that is expensive to construct and difficult to validate. The Association for the Advancement of Medical Instrumentation is developing SW91, a defect taxonomy to be published as a standard for health software. This paper details three methods to validate SW91 for its comprehensiveness. The initial validations of SW91 were conducted via mapping vulnerabilities from the common weakness enumeration and a dataset from a medical device software development company in Ireland. Taxonomy‐based testing is another validation method proposed in this research, and its applicability was investigated using empirical data from a medical device software development company in Ireland. Finally, the paper details future plans to implement taxonomy‐based testing to improve software quality in medical device software and to validate SW91. This validation will focus on the efficiency, reliability, and ability to perform useful analyses and defect coverage of SW91.
Hamsini Ketheswarasarma Rajaram, John Loane, Silvana Togneri MacMahon, Fergal McCaffery
J. Softw. Evol. Process.4
2019 To what extent the medical device software regulations can be achieved with agile software development methods? XP - DSDM - Scrum
Özden Özcan Top, Fergal McCaffery
J. Supercomput.2
2018 A Process Framework Combining Safety and Security in Practice
Fergal McCaffery, Özden Özcan Top, Ceara Treacy, Pangkaj Chandra Paul, John Loane, Jennifer Crilly, Arthur Mc Mahon
EuroSPI1
2018 A Software Process Improvement Roadmap for IEC 62304: An Expert Review
Peter Rust, Derek Flood, Gilbert Regan, Fergal McCaffery
EuroSPI4
2018 A hybrid assessment approach for medical device software development companies
abstract
Abstract Medical device software development organizations are bound by regulatory requirements and constraints to ensure that developed medical devices will not harm patients. Medical devices have to be treated as complete systems and be evaluated in this manner. Instead of manufacturers having to ensure compliance to various regulatory standards individually, the authors previously developed a medical device software process assessment framework called MDevSPICE®that integrates the regulatory requirements from all the relevant medical device software standards. The MDevSPICE®was developed in a manner that suits plan‐driven software development. To improve the usability of MDevSPICE®in agile settings, we extended the assessment approach. The hybrid assessment approach described here combines the MDevSPICE®‐based process assessment method with steps for prioritization of improvement needs through value stream mapping and enabling process improvement through the use of KATA technique. This approach integrates agile methods into the medical device software development process while adhering to the requirements of the regulatory standards. This paper describes the implementation of the approach within 4 organizations that develop software in line with medical device regulations.
Özden Özcan Top, Fergal McCaffery
J. Softw. Evol. Process.2
2017 A Lightweight Software Process Assessment Approach Based on MDevSPICE® for Medical Device Development Domain
Özden Özcan Top, Fergal McCaffery
EuroSPI2
2017 Hybrid software and system development in practice: waterfall, scrum, and beyond
abstract
Software and system development faces numerous challenges of rapidly changing markets. To address such challenges, companies and projects design and adopt specific development approaches by combining well-structured comprehensive methods and flexible agile practices. Yet, the number of methods and practices is large, and available studies argue that the actual process composition is carried out in a fairly ad-hoc manner. The present paper reports on a survey on hybrid software development approaches. We study which approaches are used in practice, how different approaches are combined, and what contextual factors influence the use and combination of hybrid software development approaches. Our results from 69 study participants show a variety of development approaches used and combined in practice. We show that most combinations follow a pattern in which a traditional process model serves as framework in which several fine-grained (agile) practices are plugged in. We further show that hybrid software development approaches are independent from the company size and external triggers. We conclude that such approaches are the results of a natural process evolution, which is mainly driven by experience, learning, and pragmatism.
Marco Kuhrmann, Philipp Diebold, Jürgen Münch, Paolo Tell, Vahid Garousi, Michael Felderer, Kitija Trektere, Fergal McCaffery, Oliver Linssen, Eckhart Hanser, Christian Prause
ICSSP8
2017 A Proposed Approach to the Revision of IEC 80001-1 Following Annex SL
Silvana Togneri MacMahon, Todd Cooper, Fergal McCaffery
SPICE3
2017 How Does Scrum Conform to the Regulatory Requirements Defined in MDevSPICE®?
Özden Özcan Top, Fergal McCaffery
SPICE2
2017 Mobile medical app development with a focus on traceability
abstract
Abstract Today, the growth of medical devices and mobile medical applications is increasing enormously, thanks to the efficiency and enhancement of new technology. When it comes to mobile medical apps, developers need to understand what is required when a mobile application fulfils the definition of a medical device. Such applications have to be developed in compliance with medical device regulations. This can be a challenge for mobile medical application developers, as medical device software is normally developed in a manner that will also ensure the production of regulatory documentation that is essential to market such devices. In this paper, we identify the need for a mobile medical application development framework, the key criteria for such a framework, and describe how the results were collected through performing a Medical Device Software Development workshop. Furthermore, we describe how MDevSPICE together with an agile software development approach can be tailored to support a mobile medical applications development framework. We detail one of the key criteria for mobile medical application development framework—traceability.
Kitija Trektere, Gilbert Regan, Fergal McCaffery, Derek Flood, Marion Lepmets, Grainne Barry
J. Softw. Evol. Process.3
2016 Situational Factors in Safety Critical Software Development
Risto Nevalainen, Paul M. Clarke, Fergal McCaffery, Rory O'Connor, Timo Varkoi
EuroSPI3
2016 Research findings from an industrial trial of a traceability assessment and implementation framework
abstract
Software systems are becoming increasingly complex. Within safety critical domains such as medical device software, this increasing complexity is placing growing demands on manufacturers who must ensure their software not only meets functional requirements but is also safe and reliable. However, the Food and Drugs Administration who regulate medical device software in the United States report a significant increase in recalls between years 2003 and 2012 and have cited software difficulties as one of the frequent causes of recalls. Furthermore a recent analysis of traceability documentation submitted to the Administration has revealed that the traceability data was incomplete, incorrect, and conflicting in many cases. This is problematic as traceability plays an important role in the development of safe and reliable software. In this paper we present the validation, through industry trial, of a traceability assessment and implementation framework which we have developed to assist medical device organizations implement traceability in an efficient and regulatory compliant manner. Our findings show that implementation of the framework within two organizations improved their traceability process and that both organizations found the framework to be both useful and usable.
Gilbert Regan, Derek Flood, Fergal McCaffery
ICSSP3
2016 Tailoring MDevSPICE® for mobile medical apps
abstract
Mobile medical apps play an important role within the healthcare industry. Developers of mobile medical apps need to understand what is required when a mobile application fulfils the definition of a medical device. Such applications have to be developed in compliance with medical device regulations. This can be a challenge for mobile medical application developers as medical device software is normally developed with a focus upon producing the regulatory documentation that is essential to market such devices. Regulatory compliance is usually achieved by adopting a plan-driven software development approach, which is not typically the method used to develop mobile applications. MDevSPICE® is a medical device software process framework that integrates processes from various medical device software and generic software development best practice standards. In this paper the authors describe how the MDevSPICE® framework can be tailored to support mobile medical applications development by introducing agile practices into the framework.
Kitija Trektere, Fergal McCaffery, Marion Lepmets, Grainne Barry
ICSSP2
2016 Risk Management: Achieving Higher Maturity & Capability Levels through the LEGO Approach
abstract
A common challenge in life is to evaluate and deal with risks. Even though Risk management is fundamental to any activity, it is too often evaluated and managed from a qualitative rather than a quantitative perspective. In order to improve, too often organizations are seeking compliance against a single model/approach, forgetting that most often 'one model doesn't fit all' and that the target process model is the organizational one, strengthened by external best practices. An approach to process improvement that takes this into consideration is LEGO (Living EnGineering prOcess). LEGO extracts the most useful Elements of Interest (EoI) from several types of maturity models into an organizational Business Process Model (BPM) in order to facilitate to the achievement of higher organizational maturity and capability levels, that's the definitive intended target to be improved. This paper applies the LEGO approach to Risk Management, analyzing several Risk Management Maturity Models and unifying their practices in order to come up with a more comprehensive process model on risk management integrating multiple views.
Luigi Buglione, Alain Abran, Christiane Gresse von Wangenheim, Fergal McCaffery, Jean C. R. Hauck
IWSM-Mensura4
2016 Safety Critical Software Development - Extending Quality Management System Practices to Achieve Compliance with Regulatory Requirements
Andrzej Beniamin Bujok, Silvana Togneri MacMahon, Fergal McCaffery, Dick Whelan, Bernard Mulcahy, William J. Rickard
SPICE3
2016 Investigating the Suitability of Using Agile for Medical Embedded Software Development
Surafel Demissie, Frank Keenan, Fergal McCaffery
SPICE3
2016 Agile - Is it Suitable for Medical Device Software Development?
Fergal McCaffery, Kitija Trektere, Özden Özcan Top
SPICE1
2016 Software Process Improvement Roadmaps - Using Design Patterns to Aid SME's Developing Medical Device Software in the Implementation of IEC 62304
Peter Rust, Derek Flood, Fergal McCaffery
SPICE3
2016 Development and benefits of MDevSPICE®, the medical device software process assessment framework
abstract
Abstract Software development companies moving into the medical device domain often find themselves overwhelmed by the number of regulatory requirements they need to satisfy before they can market their device. Several international standards and guidance documents have been developed to help companies on their road to regulatory compliance, but working their way through the various standards is a challenge in itself. In order to help software companies in the medical device domain, we have developed an integrated framework of medical device software development best practices called MDevSPICE®. This framework integrates generic software development best practices with medical device standards' requirements enabling consistent assessment of medical device processes. MDevSPICE® can be used by software companies evaluating their readiness for regulatory audits as well as by large medical device manufacturers for selecting suitable software suppliers. In this paper, we describe the development of the MDevSPICE® framework—its process reference model, process assessment model, assessment method and assessor training and certification scheme. We also illustrate the benefits and significance of the framework for the medical device‐manufacturing community as learned from the various MDevSPICE® assessments that we conducted to date. Copyright © 2016 John Wiley & Sons, Ltd.
Marion Lepmets, Fergal McCaffery, Paul M. Clarke
J. Softw. Evol. Process.2
2016 The MedITNet assessment framework: development and validation of a framework for improving risk management of medical IT networks
abstract
Abstract The use of networked medical devices can provide a number of benefits such as improved patient safety, a reduction in adverse events and reduced costs of care. Today, medical devices are increasingly designed for incorporation into a hospital's general IT network, which allows devices to exchange critical information. However, connecting devices in this way can introduce risks potentially negating the benefits to patients. While the IEC 80001‐1 standard has been developed to aid Healthcare Delivery Organisations (HDOs) in addressing these risks, HDOs often struggle to understand and implement the requirements. The MedITNet framework has been developed to allow HDOs to assess the capability of their risk management processes against the requirements of IEC 80001‐1. MedITNet provides a flexible assessment framework enabling HDOs to gain a greater understanding of the requirements of the standard and to improve risk management processes by determining their current state and highlighting areas for improvement. This paper examines the challenges faced by HDOs in the risk management of medical IT networks and briefly explains the components of the MedITNet framework and how the framework addresses these challenges. The use of Action Design Research (ADR) in the development and validation of MedITNet is also discussed focusing on a pilot implementation of the assessment method and expert review of the overall framework. The changes to the framework and its components as a result of the validation process are also discussed. Copyright © 2016 John Wiley & Sons, Ltd.
Silvana Togneri MacMahon, Fergal McCaffery, Frank Keenan
J. Softw. Evol. Process.2
2016 Creation of an IEC 62304 compliant software development plan
abstract
Abstract Organizations engaged in medical device software development are required to demonstrate compliance with a set of medical device standards and regulations before the device can be marketed. One such standard IEC 62304, Medical Device Software—Software Life Cycle Processes, defines the processes that are required in order to develop safe software. Demonstrating compliance with IEC 62304 can be problematic for organizations that are new to or have limited experience in the domain. The standard defines what processes must be carried out but does not state how. In a review of a number of such organizations, it was found that the development of a software development plan proved to be a difficult task. In this work we have created a software development plan template to assist organizations with this arduous task. The software development plan template will be validated with these organizations as part of the future work.
Peter Rust, Derek Flood, Fergal McCaffery
J. Softw. Evol. Process.3
2015 Piloting MDevSPICE: the medical device software process assessment framework
abstract
Software development companies moving into the medical device domain often find themselves overwhelmed by the number of regulatory requirements they need to satisfy before they can market their device. Several international standards and guidance documents have been developed to help companies on their road to regulatory compliance but working their way through the various standards is a challenge in itself. In order to help software companies in the medical device domain, we have developed an integrated framework of medical device software development best practices called MDevSPICE®. This framework integrates generic software development best practices with medical device standards’ requirements enabling consistent and thorough assessment of medical device processes. MDevSPICE® can be used by software companies evaluating their readiness for regulatory audits as well as by large medical device manufacturers for selecting suitable software suppliers. The MDevSPICE® framework consists of a process reference model, a process assessment model, an assessment method, and training and certification schemes. The framework has been validated using expert reviews and through MDevSPICE® assessments in industry. In this paper, we describe the MDevSPICE® process assessment framework focusing on its benefits and significance for the medical device manufacturing community as learned from MDevSPICE® assessments conducted to date.
Marion Lepmets, Fergal McCaffery, Paul M. Clarke
ICSSP2
2015 Development and validation of the MedITNet assessment framework: improving risk management of medical IT networks
abstract
The use of networked medical devices can provide a number of benefits such as improved patient safety, reduced costs of care and a reduction in adverse events. Traditionally, medical devices were placed onto a proprietary IT network provided by the manufacturer of the device. Today, medical devices are increasingly designed for incorporation into a hospital’s general IT network enabling devices to exchange critical information. However, this can introduce risks and negate the potential benefits to patients. While the IEC 80001-1 standard has been developed to aid Healthcare Delivery Organisations (HDOs) in addressing these risks, HDOs may struggle to understand and implement the requirements. The MedITNet framework has been developed to allow HDOs to assess the capability of their risk management processes against the requirements of IEC 80001-1. MedITNet provides a flexible assessment framework enabling HDOs to gain a greater understanding of the requirements of the standard and to improve risk management processes by determining their current state and highlighting areas for improvement. This paper examines the challenges faced by HDOs in the risk management of medical IT networks and briefly explains the components of the MedITNet framework and how the framework addresses these challenges. This paper also details how Action Design Research (ADR) was used in the development and validation of MedITNet.
Silvana Togneri MacMahon, Fergal McCaffery, Frank Keenan
ICSSP2
2015 Software or Service? That's the Question!
Luigi Buglione, Alain Abran, Christiane Gresse von Wangenheim, Fergal McCaffery, Jean C. R. Hauck
IWSM/Mensura4
2015 Towards an International Security Case Framework for Networked Medical Devices
Anita Finnegan, Fergal McCaffery
SAFECOMP2
2015 Safety Critical Software Process Assessment: How MDevSPICE® Addresses the Challenge of Integrating Compliance and Capability
Paul M. Clarke, Marion Lepmets, Alec Dorling, Fergal McCaffery
SPICE4
2015 The Development and Validation of a Roadmap for Traceability
Gilbert Regan, Derek Flood, Fergal McCaffery
SPICE3
2015 Software Process Improvement and Roadmapping - A Roadmap for Implementing IEC 62304 in Organizations Developing and Maintaining Medical Device Software
Peter Rust, Derek Flood, Fergal McCaffery
SPICE3
2015 A roadmap to ISO 14971 implementation
abstract
Medical device standards outline the requirements for developing medical devices. These standards, however, do not outline how these requirements should be implemented causing difficulties for organisations entering the medical device domain. The goal of this study is to validate a roadmap for the implementation of the ISO 14971 standard. The validation examined the arrangement of the milestones within the roadmap and grouping of the goals into milestones. Five experienced risk management personnel in the medical device domain were asked to complete an online questionnaire examining their opinion on the structure and content of the roadmap. Overall participants found the roadmap, in general, to be well structured and well organised and made some recommendations for improving the roadmap through merging of specific goals and rearrangement of the milestones within the roadmap. Copyright © 2015 John Wiley & Sons, Ltd.
Derek Flood, Fergal McCaffery, Valentine Casey, Ruth McKeever, Peter Rust
J. Softw. Evol. Process.2
2015 Development of MDevSPICE® - the medical device software process assessment framework
abstract
Abstract Software that is incorporated into a medical device, or which is a standalone medical device in its own right, is of a safety critical nature and subject to regulation from various jurisdictions. In order to satisfy jurisdictional regulations, developers of medical device software adopt standards and guidance provided by international standards bodies and regulators. However, the various standards and guidance documents are often not developed as a single cohesive set resulting in a complex and costly challenge for medical device software developers when complying with regulation. The aim of this paper is to describe the integration of medical device guidance documents and software engineering standards into a unified framework for medical device software process assessment called MDevSPICE®. The paper illustrates the development of both the process reference model and the process assessment model (PAM) of MDevSPICE®. The MDevSPICE® PAM can help software developers to prepare for the regulatory audits, which they must satisfy as a prerequisite to placing their products on the market. The MDevSPICE® PAM can also assist medical device manufacturers to select competent software suppliers. Copyright © 2015 John Wiley & Sons, Ltd.
Marion Lepmets, Paul M. Clarke, Fergal McCaffery, Anita Finnegan, Alec Dorling
J. Softw. Evol. Process.3
2015 Assessing traceability - practical experiences and lessons learned
abstract
Abstract Most existing software systems that lack explicit traceability links between artefacts, or if implemented, are often not leveraged to take advantage of the information it can provide to a development or validation team. Within the medical device domain, as in other safety critical domains, regulation normally requires such systems that are certified before entering service. This involves submission of a safety case (a reasoned argument that the system is acceptably safe) to the regulator. A safety case should include evidence that the organisation has established effective software development processes. At the heart of such processes, they must incorporate traceability. However, numerous barriers such as a lack of awareness of traceability and a lack of guidance as to how to implement traceability hamper its effective implementation. In this paper, we address the lack of guidance on traceability implementation by presenting our experience of developing and trialling a traceability assessment model in two medical device organisations. We show that the assessment model was successful in identifying strengths and weaknesses in both organisations' implementation of traceability. Through experience of trialling the model, we propose an idea to improve it by automation, using the Open Services for Lifecycle Collaboration initiative. Copyright © 2015 John Wiley & Sons, Ltd.
Gilbert Regan, Miklós Biró, Derek Flood, Fergal McCaffery
J. Softw. Evol. Process.4
2014 A Critical Evaluation of a Methodology for the Generation of Software Process Improvement Roadmaps
Derek Flood, Fergal McCaffery, Gilbert Regan, Valentine Casey
EuroSPI2
2014 A Traceability Process Assessment Model for the Medical Device Domain
Gilbert Regan, Miklós Biró, Fergal McCaffery, Kevin McDaid, Derek Flood
EuroSPI3
2014 MDevSPICE - A Comprehensive Solution for Manufacturers and Assessors of Safety-Critical Medical Device Software
Paul M. Clarke, Marion Lepmets, Fergal McCaffery, Anita Finnegan, Alec Dorling, Derek Flood
SPICE3
2014 A Lightweight Assessment Method for Medical Device Software Processes
Fergal McCaffery, Paul M. Clarke, Marion Lepmets
SPICE1
2014 An Agile Implementation within a Medical Device Software Organisation
Martin McHugh, Fergal McCaffery, Garret Coady
SPICE2
2014 The Development and Validation of a Traceability Assessment Model
Gilbert Regan, Fergal McCaffery, Kevin McDaid, Derek Flood
SPICE2
2014 Adopting agile practices when developing software for use in the medical domain
abstract
SUMMARY Non‐safety critical software developers have been reaping the benefits of adopting agile practices for a number of years. However, developers of safety critical software often have concerns about adopting agile practices. Through performing a literature review, this research has identified the perceived barriers to following agile practices when developing medical device software. A questionnaire‐based survey was also conducted with medical device software developers in Ireland to determine the barriers to adopting agile practices. The survey revealed that half of the respondents develop software in accordance with a plan‐driven software development lifecycle and that they believe that there are a number of perceived barriers to adopting agile practices when developing regulatory compliant software such as being contradictory to regulatory requirements, insufficient coverage of risk management activities and the lack of up‐front planning. In addition, a comparison is performed between the perceived and actual barriers. Based upon the findings of the literature review and survey, it emerged that no external barriers exist to adopting agile practices when developing medical device software and the barriers that do exists are internal barriers such as getting stakeholder buy in. Copyright © 2013 John Wiley & Sons, Ltd.
Martin McHugh, Fergal McCaffery, Valentine Casey
J. Softw. Evol. Process.2
2013 Framework to Assist Healthcare Delivery Organisations and Medical Device Manufacturers Establish Security Assurance for Networked Medical Devices
Anita Finnegan, Fergal McCaffery, Gerry Coleman
EuroSPI2
2013 A Methodology for Software Process Improvement Roadmaps for Regulated Domains - Example with IEC 62366
Derek Flood, Fergal McCaffery, Valentine Casey, Gilbert Regan
EuroSPI2
2013 Leveraging Reuse-Related Maturity Issues for Achieving Higher Maturity and Capability Levels
Luigi Buglione, Giuseppe Lami, Christiane Gresse von Wangenheim, Fergal McCaffery, Jean C. R. Hauck
ICSR4
2013 Risk management of medical IT networks: an ISO/IEC 15504 compliant approach to assessment against IEC 80001-1
abstract
The incorporation of a medical device into an IT network can introduce risks that may not have been addressed during the design and manufacture of the device. IEC 80001-1 is a lifecycle risk management standard which was developed to address these risks. This paper presents research which has been performed to date which has led to the development of a Process Reference Model (PRM) and Process Assessment Model (PAM) which can be used by Healthcare Delivery Organisations to assess themselves against IEC 80001-1. This paper also presents future work in this area which includes the development of an assessment method for IEC 80001-1 and the validation of the PRM, PAM and assessment method.
Silvana Togneri MacMahon, Fergal McCaffery, Frank Keenan
ICSSP2
2013 A Security Assurance Framework for Networked Medical Devices
Anita Finnegan, Fergal McCaffery, Gerry Coleman
PROFES2
2013 The Development and Current Status of Medi SPICE
Valentine Casey, Fergal McCaffery
SPICE2
2013 A Process Assessment Model for Security Assurance of Networked Medical Devices
Anita Finnegan, Fergal McCaffery, Gerry Coleman
SPICE2
2013 The Approach to the Development of an Assessment Method for IEC 80001-1
Silvana Togneri MacMahon, Fergal McCaffery, Frank Keenan
SPICE2
2013 Balancing Agility and Discipline in a Medical Device Software Organisation
Martin McHugh, Fergal McCaffery, Brian Fitzgerald 0001, Klaas-Jan Stol, Valentine Casey, Garret Coady
SPICE2
2013 Investigation of Traceability within a Medical Device Organization
Gilbert Regan, Fergal McCaffery, Kevin McDaid, Derek Flood
SPICE2
2013 A lightweight traceability assessment method for medical device software
abstract
SUMMARY Traceability is central to medical device software development and essential for regulatory approval. For compliance to be achieved, an effective traceability process needs to be in place. This process must ensure the need for clear linkages and traceability from software requirements – including risks – through the different stages of the software development and maintenance lifecycles. This is difficult to achieve because of the lack of specific guidance within the medical device standards and documentation. This has resulted in many medical device companies employing inefficient software traceability processes. In this paper, we outline the development and implementation of Med‐Trace, a lightweight software traceability process assessment and improvement method developed specifically for the medical device industry. We also present and discuss findings from two industry‐based Med‐Trace assessments. Copyright © 2011 John Wiley & Sons, Ltd.
Valentine Casey, Fergal McCaffery
J. Softw. Evol. Process.2
2012 Hybriding CMMI and Requirement Engineering Maturity & Capability Models - Applying the LEGO Approach for Improving Estimates
Luigi Buglione, Jean C. R. Hauck, Christiane Gresse von Wangenheim, Fergal McCaffery
ICSOFT4
2012 Medi SPICE and the Development of a Process Reference Model for Inclusion in IEC 62304
abstract
The demand for medical device software continues to grow and there is an associated increase in its importance and complexity.This paper discusses medical device software process assessment and improvement.It outlines Medi SPICE, a software process assessment and improvement model which is being developed to meet the specific safety-critical and regulatory requirements of the medical device domain.It also details the development of a subset of the Medi SPICE process reference model for inclusion in the next release of the IEC 62304 standard: Medical device software -Software life cycle processes.IEC 62304 is a key standard for medical device software development and is approved by many national regulatory bodies including the Food and Drug Administration in the United States and the European Union.This paper also outlines 3 lightweight software process assessment methods which have been developed in tandem with Medi SPICE.Finally the timeline for the release of the full Medi SPICE model is provided.
Valentine Casey, Fergal McCaffery
ICSOFT2
2012 FIRST: Common-Sense Process Scopes for Starting a Process Improvement Program
Luigi Buglione, Fergal McCaffery, Jean C. R. Hauck, Christiane Gresse von Wangenheim
SPICE2
2012 Development of the Medi SPICE PRM
Valentine Casey, Fergal McCaffery
SPICE2
2012 The Gamification of SPICE
Alec Dorling, Fergal McCaffery
SPICE2
2012 Development of a Process Assessment Model for Assessing Medical IT Networks against IEC 80001-1
Silvana Togneri MacMahon, Fergal McCaffery, Sherman Eagles, Frank Keenan, Marion Lepmets, Alain Renault
SPICE2
2012 Barriers to Adopting Agile Practices When Developing Medical Device Software
Martin McHugh, Fergal McCaffery, Valentine Casey
SPICE2
2012 Traceability-Why Do It?
Gilbert Regan, Fergal McCaffery, Kevin McDaid, Derek Flood
SPICE2
2012 A Process Framework for Global Software Engineering Teams
Ita Richardson, Valentine Casey, Fergal McCaffery, John Burton, Sarah Beecham
Inf. Softw. Technol.3
2012 An agile process model for product derivation in software product line engineering
abstract
SUMMARY Software product lines (SPL) and Agile practices have emerged as new paradigms for developing software. Both approaches share common goals; such as improving productivity, reducing time to market, decreasing development costs and increasing customer satisfaction. These common goals provide the motivation for this research. We believe that integrating Agile practices into SPL can bring a balance between agility and formalism. However, there has been a little research on such integration. We have been researching the potential of integrating Agile approaches in one of the key SPL process areas, product derivation (PD). In this paper, we present an outline of our Agile process model for PD that was developed through industry‐based case study research. Copyright © 2010 John Wiley & Sons, Ltd.
Pádraig O'Leary, Fergal McCaffery, Steffen Thiel, Ita Richardson
J. Softw. Evol. Process.2
2011 How Can Software SMEs Become Medical Device Software SMEs
Fergal McCaffery, Valentine Casey, Martin McHugh
EuroSPI1
2011 Improving Verification & Validation in the Medical Device Domain
M. S. Sivakumar, Valentine Casey, Fergal McCaffery, Gerry Coleman
EuroSPI3
2011 Proposing an ISO/IEC 15504-2 Compliant Method for Process Capability/Maturity Models Customization
Jean C. R. Hauck, Christiane Gresse von Wangenheim, Fergal McCaffery, Luigi Buglione
PROFES3
2011 Challenges for Requirements Development: An Industry Perspective
Sandra Kelly, Frank Keenan, Fergal McCaffery
SPICE3
2011 Med-Trace
Fergal McCaffery, Valentine Casey
SPICE1
2011 Standalone Software as an Active Medical Device
Martin McHugh, Fergal McCaffery, Valentine Casey
SPICE2
2011 Verification & Validation in Medi SPICE
M. S. Sivakumar, Valentine Casey, Fergal McCaffery, Gerry Coleman
SPICE3
2010 AnnoTestWeb/Run: Annotations Based Acceptance Testing
David Connolly, Frank Keenan, Fergal McCaffery
XP3
2010 Medi SPICE development
abstract
Abstract This article outlines the development of a software process assessment and improvement model (Medi SPICE) for the medical device industry. The article details how medical device regulations may be satisfied by extending relevant processes and practices from ISO/IEC 15504‐5. The article also describes the proposed phases of delivery for Medi SPICE. Medi SPICE will define a process reference model, process assessment model (PAM) and organizational maturity model (OMM). The Medi SPICE PAM will be used to perform ISO/IEC 15504 conformant assessments of the software process capability of medical device suppliers in accordance with the requirements of ISO/IEC 15504‐2: 2003. The Medi SPICE Process Assessment Model will be based on ISO/IEC 15504‐5: 2006 and shall be extended to provide coverage of additional software development practices that are required to achieve regulatory compliance within the medical device industry. The processes will be defined within an OMM conformant with ISO/IEC TR 15504‐7:2008. Copyright © 2009 John Wiley & Sons, Ltd.
Fergal McCaffery, Alec Dorling
J. Softw. Maintenance Res. Pract.1
2010 Risk management capability model for the development of medical device software
Fergal McCaffery, John Burton, Ita Richardson
Softw. Qual. J.1
2009 Automating Expert-Defined Tests: A Suitable Approach for the Medical Device Industry?
David Connolly, Fergal McCaffery, Frank Keenan
EuroSPI2
2009 Preparing for Product Derivation - Activities and Issues
Pádraig O'Leary, Ita Richardson, Fergal McCaffery, Steffen Thiel
ICSOFT (1)3
2009 Spreadsheet Information Retrieval through Natural Language
Derek Flood, Kevin McDaid, Fergal McCaffery
NLDB3
2008 Ahaa --agile, hybrid assessment method for automotive, safety critical smes
abstract
The need for software is increasingly growing in the automotive industry. Software development projects are, however, often troubled by time and budget overruns, resulting in systems that do not fulfill customer requirements. Both research and industry lack strategies to combine reducing the long software development lifecycles (as required by time-to-market demands) with increasing the quality of the software developed. Software process improvement (SPI) provides the first step in the move towards software quality, and assessments are a vital part of this process. Unfortunately, software process assessments are often expensive and time consuming. Additionally, they often provide companies with a long list of issues without providing realistic suggestions. The goal of this paper is to describe a new low-overhead assessment method that has been designed specifically for small-to-medium-sized (SMEs) organisations wishing to be automotive software suppliers. This assessment method integrates the structured-ness of the plan-driven SPI models of Capability Maturity Model Integration (CMMI) and Automotive SPICE with the flexibleness of agile practices.
Fergal McCaffery, Minna Pikkarainen, Ita Richardson
ICSE1
2006 Experimenting with Agile Practices - First Things First
Fergal Downey, Gerry Coleman, Fergal McCaffery
XP3
2005 Improving the Express Process Appraisal Method
Fergal McCaffery, Donald McFall, F. George Wilkie
PROFES1